Getting small defense contractors ready for a CMMC Level 2 assessment
We do the technical implementation in Microsoft 365 and Intune, and build the evidence your assessor will ask to see.
Book a scoping callSecurity controls
Each one has to be implemented and evidenced.
Control families
From Access Control to System & Information Integrity.
Small team doing it all
Most small businesses have no one whose job this is.
Where most small contractors get stuck
These four problems account for most of the delay and rework we see.
No defined CUI boundary
Nobody has written down where Controlled Unclassified Information actually lives, so the scope of the work keeps changing and the cost keeps growing.
Unmanaged endpoints outside Intune
Laptops on the shop floor, a shared machine in the office, or a personal device pulling email. If a device is not managed, its settings cannot be proven.
No evidence trail for controls already in place
The setting is turned on, but there is no export, screenshot, or report showing it is on and has stayed on. An assessor cannot accept what you cannot show.
Treating it as paperwork instead of configuration
A policy document that says devices are encrypted does not encrypt devices. Most of this work happens in the tenant, not in a binder.
What we implement
Each item below is a configuration project with a defined end state and evidence you can hand to an assessor.
Intune device baselines mapped to NIST SP 800-171
Standard device configuration profiles built and enforced in Microsoft Intune, with each setting tied back to a specific NIST SP 800-171 requirement.
BitLocker encryption and recovery key escrow
Full-disk encryption on every managed Windows device, with recovery keys stored centrally so a lost laptop is a recoverable event, not an incident.
Blocking unauthorized remote access tools
Application control and network rules that stop staff from installing consumer remote-access software that bypasses your approved support path.
Session lock and screen timeout enforcement
Policy-enforced screen lock and inactivity timeout across workstations, so unattended machines are not an open door on the shop floor.
Local admin password management (LAPS) and credential protection
Unique, rotating local administrator passwords per device, plus credential protection settings that limit what an attacker can reuse.
Removable media and device control
Rules that govern USB drives and other removable media, including read-only or blocked states and logging of what was connected.
Conditional Access and MFA enforcement
Sign-in policies that require multi-factor authentication and only allow access from devices and locations you have approved.
Microsoft 365 configuration for CUI handling
Tenant, mail, and file-sharing settings configured so Controlled Unclassified Information stays inside the boundary you have defined.
How the work maps to the control families
Every CMMC Level 2 family is either configured by us, documented with your governance partner, or both. Control counts are from NIST SP 800-171.
| Control family | Controls | What KBTS does | Type |
|---|---|---|---|
ACAccess Control | 22 | Entra ID roles, Conditional Access, least-privilege file access | Configuration |
ATAwareness & Training | 3 | Security awareness training rollout and completion records | Both |
AUAudit & Accountability | 9 | Microsoft 365 audit logging, retention, log review reports | Configuration |
CMConfiguration Management | 9 | Intune baselines, app control, change records | Configuration |
IAIdentification & Authentication | 11 | MFA enforcement, password policy, device identity | Configuration |
IRIncident Response | 3 | Alerting and response runbooks; plan owned with your vCISO | Both |
MAMaintenance | 6 | Patching, remote maintenance controls, maintenance records | Configuration |
MPMedia Protection | 9 | BitLocker with escrowed keys, removable media restrictions | Configuration |
PSPersonnel Security | 2 | Onboarding and offboarding account procedures | Both |
PEPhysical Protection | 6 | Documented by your vCISO; we support device inventory | Documentation |
RARisk Assessment | 3 | Vulnerability scanning and remediation reporting | Configuration |
CASecurity Assessment | 4 | Evidence packages; SSP and POA&M owned by your vCISO | Both |
SCSystem & Communications Protection | 16 | Email security, DNS filtering, encryption in transit, network segmentation | Configuration |
SISystem & Information Integrity | 7 | Defender for Endpoint, monitoring, update management | Configuration |
Control counts are from NIST SP 800-171 Revision 2, the revision CMMC Level 2 is currently based on.
Everything tracked in one place
The governance side runs a compliance platform that maps every tool and configuration we deploy to the specific NIST SP 800-171 controls it satisfies. You see progress against all 110 controls instead of a spreadsheet nobody trusts.
- Maps each control to the system that satisfies it
- Tracks implementation status across all 110 controls
- Generates and maintains the System Security Plan
- Manages the Plan of Action and Milestones
- Keeps the SPRS score current as work lands
- Collects evidence in the form an assessor expects
How we work with your assessor
Two different jobs, handled by two different teams, so nothing falls between them.
Governance is handled separately
Our governance partner acts as your vCISO and owns the written side of the program: scoping the CUI boundary, writing the System Security Plan, maintaining the POA&M, drafting policy, and running the readiness assessment before you engage a C3PAO. KBTS stays in its lane: configuring the systems and producing the evidence that supports what they document.
KBTS handles implementation and evidence
We configure the systems the plan describes, in Microsoft 365, Intune, and on your devices. Then we produce the reports, exports, and records that show each control is in place and staying in place, so the plan and the systems match.
Depending on what your contract requires, CMMC Level 2 is either self-assessed by the contractor or assessed by a C3PAO, an independent third-party assessment organization. KBTS does not certify anyone. We prepare your configuration and evidence for either path.
Your IT provider is in scope too
Under CMMC, a managed service provider that stores, processes, or transmits Controlled Unclassified Information on a contractor's behalf, or that provides security protection for it, falls inside the assessment scope. An assessor will ask about your IT provider.
KBTS has addressed its own environment and can document how we access and support your systems. Most providers have not considered this and it surfaces late, during assessment.
What we have already done
Configuration running in production today, not a methodology slide.
Five defense supply-chain tenants
Currently running these baselines in production under active CMMC Level 2 preparation.
Deployed across every managed endpoint
Device baselines, encryption, and access policy applied and verified on every enrolled Windows device across those tenants.
Every setting proven, not assumed
A policy can be saved and still not apply. We verify each control landed on every enrolled device and produce the export or report that shows it, which is the part an assessor actually asks for.
Common questions
Start with a scoping call
Tell us what your contract requires and what you have today. We will tell you what the work looks like before you commit to anything.
Based in Plainville, Connecticut. Working with defense contractors across New England.
